yes. Youhave to search for the code in all files.
I know its tedious, but it has to be done to trace out the problem.
anothr solution would be to create another install in the subfolder using the db dump from the current site. If the new one doesnt produce that mysterious code, you can simply replace the live site with the new install.
Analyze your raw Apache access files. I noticed not only the frontend files have these JS injected, but also your manager/index.php file.
Look for unusual query strings and POSTs.
Do you have any kind of form on your site? Contact form, blog comments (Jot?)... If so, look for these pages in the log files first.
Also, ask your hosting company if they of other such attacks. It might be something they’re aware of.
Check permissions: Don’t use too high permissions where it’s simply not needed (chmod).
-
MODX Staff
- 12,272 Posts
What version of MODx are you running?
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
Faithfully using MODx since 2007!
Quote from: ganeshXL at May 23, 2009, 01:00 AM
Analyze your raw Apache access files. I noticed not only the frontend files have these JS injected, but also your manager/index.php file.
Look for unusual query strings and POSTs.
Do you have any kind of form on your site? Contact form, blog comments (Jot?)... If so, look for these pages in the log files first.
Also, ask your hosting company if they of other such attacks. It might be something they’re aware of.
Check permissions: Don’t use too high permissions where it’s simply not needed (chmod).
I’m using a contact form on the site.
Faithfully using MODx since 2007!
Quote from: runningthingz at May 23, 2009, 07:28 PM
I’m using a contact form on the site.
Your own, eForm, or SPForm?
There are 2 places you can look - files and database.
The easiest way may be to:
1. Download all of the files of the site onto your local computer.
2. Do a sitewide search through all of the files you downloaded for "Xtnwx"
3. Go to phpmyadmin and find your modx database
4. Click search
5. Type "Xtnwx" and click go
You should be able to find the code from one of those places.
6. Remove it from either the file and/or database
7. It would be good to look for more security on your site so you dont have to deal with this again. You may want to hire someone to do a quick security overview for you.
Chuck
... and upgrade to 0963 too when you complete the cleanup.